Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which nodes are supported in a distributed Cisco ISE deployment?

Options:

A.

Policy Service nodes tor automatic failover


B.

Administration nodes for session failover


C.

Monitoring nodes for PxGrid services


D.

Policy Service nodes for session failover


Expert Solution
Questions # 32:

What are two differences of TACACS+ compared to RADIUS? (Choose two.)

Options:

A.

TACACS+ uses a connectionless transport protocol, whereas RADIUS uses a connection-oriented transport protocol.


B.

TACACS+ encrypts the full packet payload, whereas RADIUS only encrypts the password.


C.

TACACS+ only encrypts the password, whereas RADIUS encrypts the full packet payload.


D.

TACACS+ uses a connection-oriented transport protocol, whereas RADIUS uses a connectionless transport protocol.


E.

TACACS+ supports multiple sessions per user, whereas RADIUS supports one session per user.


Expert Solution
Questions # 33:

During BYOD flow, from where does a Microsoft Windows PC download the Network Setup Assistant?

Options:

A.

Cisco App Store


B.

Microsoft App Store


C.

Cisco ISE directly


D.

Native OTA functionality


Expert Solution
Questions # 34:

If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

Options:

A.

Client Provisioning


B.

Guest


C.

BYOD


D.

Blacklist


Expert Solution
Questions # 35:

An engineer is assigned to enhance security across the campus network. The task is to enable MAB across all access switches in the network. Which command must be entered on the switch to enable MAB?

Options:

A.

Switch(config-if)# mab


B.

Switch(config)# mab


C.

Switch# authentication port-control auto


D.

Switch(config)# authentication port-control auto


Expert Solution
Questions # 36:

An administrator adds a new network device to the Cisco ISE configuration to authenticate endpoints to the network. The RADIUS test fails after the administrator configures all of the settings in Cisco ISE and adds the proper configurations to the switch. What is the issue"?

Options:

A.

The endpoint profile is showing as "unknown."


B.

The endpoint does not have the appropriate credentials for network access.


C.

The shared secret is incorrect on the switch or on Cisco ISE.


D.

The certificate on the switch is self-signed not a CA-provided certificate.


Expert Solution
Questions # 37:

Which type of identity store allows for creating single-use access credentials in Cisco ISE?

Options:

A.

OpenLDAP


B.

Local


C.

PKI


D.

RSA SecurID


Expert Solution
Questions # 38:

Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )

Options:

A.

External TACACS Servers


B.

Device Admin Service


C.

Device Administration License


D.

Server Sequence


E.

Command Sets


Expert Solution
Questions # 39:

Which port does Cisco ISE use for native supplicant provisioning of a Windows laptop?

Options:

A.

TCP 8909


B.

TCP 8905


C.

UDP 1812


D.

TCP 443


Expert Solution
Questions # 40:

A Cisco ISE engineer is creating a certificate authentication profile to be used with machine authentication for the network. The engineer wants to be able to compare the user-presented certificate with a certificate stored in Active Directory. What must be done to accomplish this?

Options:

A.

Configure the user-presented password hash and a hash stored in Active Directory for comparison


B.

Add the subject alternative name and the common name to the CAP.


C.

Enable the option for performing binary comparison.


D.

Use MS-CHAPv2 since it provides machine credentials and matches them to credentials stored in Active Directory


Expert Solution
Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions